|
e107 contains a flaw that may allow an attacker to upload and execute arbitrary php code. The issue is triggered when a would be attacker uploads a crafted php file with the extension ".php.filetypesphp" as their avatar or photograph image and then access the url for their image in order to invoke the php code.
|